For the complete documentation index, see llms.txt. This page is also available as Markdown.

Chrome OS Remote Access policy was modified in Google Workspace

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Google Workspace Audit Logs

Detection Modules

Identity Threat Module, SaaS Threat Detection

Detector Tags

Google Workspace

ATT&CK Tactic

Lateral Movement (TA0008), Defense Impairment (TA0112)

ATT&CK Technique

Disable or Modify Tools (T1685), Remote Services (T1021)

Severity

Informational

Description

A user modified Chrome OS Remote Access configuration in Google Workspace.

Attacker's Goals

Adversaries may modify remote access settings to maintain persistent access and bypass security controls.

Investigative actions

  • Verify if the configuration change was authorized.

  • Investigate the source IP address and account involved for malicious activity.

  • Follow further actions performed by the account and Remote Access connections performed.

Variations

Suspicious Chrome OS Remote Access policy was modified in Google Workspace

Synopsis

Field
Value

ATT&CK Tactic

Lateral Movement (TA0008), Defense Impairment (TA0112)

ATT&CK Technique

Disable or Modify Tools (T1685), Remote Services (T1021)

Severity

Low

Description

A user modified Chrome OS Remote Access configuration in Google Workspace.

  • This is the first time the user performs this operation in the last 30 days.

Attacker's Goals

Adversaries may modify remote access settings to maintain persistent access and bypass security controls.

Investigative actions

  • Verify if the configuration change was authorized.

  • Investigate the source IP address and account involved for malicious activity.

  • Follow further actions performed by the account and Remote Access connections performed.

Was this helpful?